Instruction Tuning for Secure Code Generation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: He, Jingxuan, Vero, Mark, Krasnopolska, Gabriela, Vechev, Martin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909252030824448
author He, Jingxuan
Vero, Mark
Krasnopolska, Gabriela
Vechev, Martin
author_facet He, Jingxuan
Vero, Mark
Krasnopolska, Gabriela
Vechev, Martin
contents Modern language models (LMs) have gained widespread acceptance in everyday and professional contexts, particularly in programming. An essential procedure enabling this adoption is instruction tuning, which substantially enhances LMs' practical utility by training them to follow user instructions and human preferences. However, existing instruction tuning schemes overlook a crucial aspect: the security of generated code. As a result, even the state-of-the-art instruction-tuned LMs frequently produce unsafe code, posing significant security risks. In this work, we introduce SafeCoder to address this gap. SafeCoder performs security-centric fine-tuning using a diverse and high-quality dataset that we collected using an automated pipeline. We integrate the security fine-tuning with standard instruction tuning, to facilitate a joint optimization of both security and utility. Despite its simplicity, we show that SafeCoder is effective across a variety of popular LMs and datasets. It is able to drastically improve security (by about 30%), while preserving utility.
format Preprint
id arxiv_https___arxiv_org_abs_2402_09497
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Instruction Tuning for Secure Code Generation
He, Jingxuan
Vero, Mark
Krasnopolska, Gabriela
Vechev, Martin
Cryptography and Security
Artificial Intelligence
Machine Learning
Software Engineering
Modern language models (LMs) have gained widespread acceptance in everyday and professional contexts, particularly in programming. An essential procedure enabling this adoption is instruction tuning, which substantially enhances LMs' practical utility by training them to follow user instructions and human preferences. However, existing instruction tuning schemes overlook a crucial aspect: the security of generated code. As a result, even the state-of-the-art instruction-tuned LMs frequently produce unsafe code, posing significant security risks. In this work, we introduce SafeCoder to address this gap. SafeCoder performs security-centric fine-tuning using a diverse and high-quality dataset that we collected using an automated pipeline. We integrate the security fine-tuning with standard instruction tuning, to facilitate a joint optimization of both security and utility. Despite its simplicity, we show that SafeCoder is effective across a variety of popular LMs and datasets. It is able to drastically improve security (by about 30%), while preserving utility.
title Instruction Tuning for Secure Code Generation
topic Cryptography and Security
Artificial Intelligence
Machine Learning
Software Engineering
url https://arxiv.org/abs/2402.09497